LabHost ¿Éµ¼ÖÂÈκÎÈ˶ԼÓÄôóÒøÐÐÓû§¾ÙÐÐÍøÂç´¹ÂÚ

Ðû²¼Ê±¼ä 2024-02-29

1. LabHost ¿Éµ¼ÖÂÈκÎÈ˶ԼÓÄôóÒøÐÐÓû§¾ÙÐÐÍøÂç´¹ÂÚ


2ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬ÍøÂç´¹ÂÚ (PhaaS) ƽ̨¡°LabHost¡±Ò»Ö±ÔÚ×ÊÖúÍøÂç·¸·¨·Ö×ÓÃé×¼±±ÃÀÒøÐУ¬£¬£¬£¬£¬£¬ÌØÊâÊǼÓÄôóµÄ½ðÈÚ»ú¹¹£¬£¬£¬£¬£¬£¬µ¼Ö»ÏÔ×ÅÔöÌí¡£¡£¡£PhaaS Æ½Ì¨ÎªÍøÂç·¸·¨·Ö×ÓÌṩ½»Ô¿³×ÍøÂç´¹ÂÚÌ×¼þ¡¢ÍйÜÒ³ÃæµÄ»ù´¡ÉèÊ©¡¢µç×ÓÓʼþÄÚÈÝÌìÉúºÍ»î¶¯¸ÅÊöЧÀÍ£¬£¬£¬£¬£¬£¬ÒÔ»»È¡Ã¿Ô¶©ÔÄ¡£¡£¡£LabHost ²¢²»ÊÇÒ»¼ÒÐÂÌṩÉÌ£¬£¬£¬£¬£¬£¬µ«ÔÚ 2023 ÄêÉϰëÄêΪ¼ÓÄôóÒøÐÐÍÆ³ö¶¨ÖÆÍøÂç´¹ÂÚ¹¤¾ß°üºó£¬£¬£¬£¬£¬£¬ÆäÊܽӴýˮƽì­Éý¡£¡£¡£ÍøÂç´¹ÂÚ¼´Ð§ÀÍÆ½Ì¨Ê¹²»ÊìÁ·µÄºÚ¿Í¸üÈÝÒ×ʵÑéÍøÂç·¸·¨£¬£¬£¬£¬£¬£¬´Ó¶øÏÔ×ÅÀ©´óÁËÍþвÐÐΪÕߵĹæÄ££¬£¬£¬£¬£¬£¬²¢ÔÚ¸üÆÕ±éµÄ¹æÄ£ÄÚÓ°ÏìÍøÂçÇå¾²¡£¡£¡£Ñо¿Ö°Ô±×î½üÖÒÑÔµÄÆäËûÖøÃû PhaaS ƽ̨°üÀ¨¡° Greatness ¡±ºÍ¡° Robin Banks ¡±£¬£¬£¬£¬£¬£¬ËüÃǾùÓÚ 2022 ÄêÖÐÆÚÍÆ³ö£¬£¬£¬£¬£¬£¬¾ßÓÐ MFA ÈÆ¹ý¡¢×Ô½çËµÍøÂç´¹ÂÚ¹¤¾ß°üºÍÖÎÀíÃæ°å¡£¡£¡£


https://www.bleepingcomputer.com/news/security/labhost-cybercrime-service-lets-anyone-phish-canadian-bank-users/


2. U-Haul ±¨¸æ 67000 Ãû¿Í»§Êܵ½Êý¾Ýй¶µÄÓ°Ïì


2ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬U-Haul ÊÇÒ»¼ÒλÓÚÑÇÀûÉ£ÄÇÖݵĿ¨³µ¡¢ÍϳµºÍ×ÔÖú²Ö´¢×âÁÞ¹«Ë¾£¬£¬£¬£¬£¬£¬È¥ÄêÄêµ×ÒÑ×îÏÈÏò 67,000 Ãû¿Í»§×ª´ïÊý¾Ýй¶ÊÂÎñ£¬£¬£¬£¬£¬£¬¸ÃÊÂÎñµ¼ÖÂËûÃǵÄСÎÒ˽¼ÒÐÅÏ¢Ô⵽й¶¡£¡£¡£¸ÃÎó²î±¬·¢ÔÚ 12 Ô 5 ÈÕ£¬£¬£¬£¬£¬£¬Æäʱδ¾­ÊÚȨµÄ¹¥»÷ÕßÒÔijÖÖ·½·¨Ê¹ÓÃÕýµ±Æ¾Ö¤»á¼ûU-Haul¾­ÏúÉ̺ÍÍŶӳÉÔ±ÓÃÀ´¸ú×Ù¿Í»§Ô¤¶©ºÍÉó²é¿Í»§¼Í¼µÄϵͳ¡£¡£¡£U-Haul ·¢Ã÷ÕâÒ»ÊÂÎñºó£¬£¬£¬£¬£¬£¬Á¬Ã¦Æô¶¯ÁËÏìӦЭÒ飬£¬£¬£¬£¬£¬²¢ÓëÒ»¼ÒÍøÂçÇå¾²¹«Ë¾Ò»Æð¶Ô´Ë´Îй¶ÊÂÎñÕö¿ªÁËÊӲ졣¡£¡£ÊÓ²ìÏÔʾ£¬£¬£¬£¬£¬£¬Ä³Ð©¿Í»§¼Í¼ÔÚ´Ë´Îй¶Öб»»á¼û£¬£¬£¬£¬£¬£¬°üÀ¨ÆÜÉíÔÚÃåÒòÖÝµÄ 136 ÃûСÎÒ˽¼ÒµÄÐÕÃûºÍ¼ÝʻִÕÕÐÅÏ¢¡£¡£¡£U-HaulÔÚ¸øÊÜÓ°ÏìСÎÒ˽¼ÒµÄ֪ͨÐÅÖÐÖ¸³ö£¬£¬£¬£¬£¬£¬´Ë´ÎÎ¥¹æÊÂÎñÉæ¼°µÄ¿Í»§¼Í¼ϵͳδÅþÁ¬µ½Ö§¸¶ÏµÍ³£¬£¬£¬£¬£¬£¬Òò´ËÍþвÐÐΪÕßûÓлá¼ûÈκÎÒøÐп¨Êý¾Ý¡£¡£¡£È»¶ø£¬£¬£¬£¬£¬£¬¹ØÓÚ×âÁÞ¹«Ë¾À´Ëµ£¬£¬£¬£¬£¬£¬ÕâÖÖÎ¥¹æÐÐΪ²¢²»ÊǵÚÒ»´Î¡£¡£¡£


https://www.darkreading.com/cyberattacks-data-breaches/67k-customers-impacted-by-data-breach-according-to-u-haul


3. Õë¶Ô UnitedHealth Optum µÄ¹¥»÷µ¼ÖÂÒ½ÁƱ£½¡¼Æ·ÑÖÐÖ¹


2ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬È«ÇòÊÕÈë×î´óµÄÒ½ÁƱ£½¡¹«Ë¾ÁªºÏ¿µ½¡¼¯ÍÅ (UnitedHealth Group) ֤ʵ£¬£¬£¬£¬£¬£¬Æä×Ó¹«Ë¾ Optum ×î½üÔÚ Change Healthcare ¼Æ·Ñƽ̨ÉÏÔâÓöÁËÑÏÖØµÄÍøÂç¹¥»÷¡£¡£¡£´Ë´Î¹¥»÷µ¼ÖÂÃÀ¹ú¸÷µØÒ½ÁƱ£½¡¼Æ·ÑЧÀÍÑÏÖØÖÐÖ¹£¬£¬£¬£¬£¬£¬¸øÌìϹæÄ£ÄÚµÄÒ½ÁÆÕïËù¡¢Ò©·¿ºÍ°ü¹ÜÌṩÉÌÔì³ÉÔÓÂÒ¡£¡£¡£Æ¾Ö¤ UnitedHealth µÄÉùÃ÷£¬£¬£¬£¬£¬£¬´Ë´Î¹¥»÷ÒÉËÆÓÉÂÄÀú¸»ºñµÄÃñ×å¹ú¼ÒºÚ¿ÍËùΪ£¬£¬£¬£¬£¬£¬ËûÃÇÄܹ»ÉøÍ¸ Optum µÄϵͳ²¢ÆÈʹ¸Ã¹«Ë¾¹Ø±Õ IT »ù´¡ÉèÊ©ÒÔ×èÖ¹Íþв¡£¡£¡£Êܵ½¹¥»÷µÄ Change Healthcare ƽ̨¹ØÓÚÔö½øÒ½ÁƱ£½¡ÌṩÕßÖ®¼äµÄÖ§¸¶½»Á÷ÖÁ¹ØÖ÷Òª£¬£¬£¬£¬£¬£¬´Ó¶øÊµÏÖµç×Ó¿µ½¡¼Í¼¡¢Ë÷Åâ´¦Öóͷ£¡¢Õչ˻¤Ê¿Ð­Ð­µ÷Êý¾ÝÆÊÎöµÈÒªº¦¹¦Ð§¡£¡£¡£ÓÉÓÚÎÞ·¨Ê¹Óà Optum µÄ¼Æ·Ñ¹¤¾ß£¬£¬£¬£¬£¬£¬Ðí¶àÒ©·¿¡¢ÕïËùºÍÒ½ÁƼƷѹ«Ë¾¶¼±¨¸æÁËÑÏÖØµÄÔËÓªÌôÕ½ºÍÔ¤Ô¼ÖÐÖ¹¡£¡£¡£Õâ´ÎÍ£µçÀ´µÃ×ÅʵÊÇÌ«Ôã¸âÁË£¬£¬£¬£¬£¬£¬ÓÉÓÚÒ½ÁƱ£½¡ÌṩÕßÕýÔÚÓ¦¶ÔÒ½ÁÆÐ§ÀÍÐèÇóµÄ¼¤Ôö¡£¡£¡£ÔÚ Optum ÍêÈ«»Ö¸´Ð§ÀÍ֮ǰ£¬£¬£¬£¬£¬£¬Ó°ÏìÔ¤¼Æ½«Ò»Á¬ÊýÌìÉõÖÁÊýÖÜ¡£¡£¡£


https://securityboulevard.com/2024/02/major-cyberattack-on-unitedhealths-optum-causes-widespread-healthcare-billing-disruption/


4. LoanDepot³ÆÔ¼ 1700 Íò¿Í»§µÄÐÅÏ¢ÔÚÍøÂç¹¥»÷ʱ´ú±»µÁ


2ÔÂ26ÈÕ£¬£¬£¬£¬£¬£¬LoanDepot ÒÑ֤ʵ£¬£¬£¬£¬£¬£¬½ü 1700 Íò LoanDepot ¿Í»§µÄÃô¸ÐСÎÒ˽¼ÒÐÅÏ¢£¨°üÀ¨Éç»áÇå¾²ºÅÂ룩ÔÚ 1 Ô·ݵÄÀÕË÷Èí¼þ¹¥»÷Öб»µÁ¡£¡£¡£Õâ¼Ò´û¿îºÍµäÖÊ´û¿î¾ÞÍ·¹«Ë¾ÔÚÏòÃåÒòÖÝ×ÜÉó²é³¤°ì¹«ÊÒÌá½»µÄÊý¾Ýй¶֪ͨÖÐÌåÏÖ£¬£¬£¬£¬£¬£¬±»µÁµÄ LoanDepot ¿Í»§Êý¾Ý°üÀ¨ÐÕÃû¡¢³öÉúÈÕÆÚ¡¢µç×ÓÓʼþºÍÓÊÕþµØµã¡¢²ÆÎñÕʺź͵绰ºÅÂë¡£¡£¡£±»µÁÊý¾Ý»¹°üÀ¨ LoanDepot ´Ó¿Í»§ÄÇÀïÍøÂçµÄÉç»áÇå¾²ºÅÂë¡£¡£¡£ÊÜÓ°ÏìµÄ LoanDepot ¿Í»§ÊýÄ¿½ÏÉϸöÔÂ×î³õÏòÁª°îî¿Ïµ»ú¹¹Åû¶µÄ1660 ÍòÓÐËùÔöÌí£¬£¬£¬£¬£¬£¬Áª°îî¿Ïµ»ú¹¹²¢Î´Í¸Â¶ÏêϸÄÄЩ¿Í»§Êý¾Ý±»µÁ¡£¡£¡£´Ë´ÎÍøÂç¹¥»÷µ¼Ö LoanDepot µÄÊý°ÙÍò¿Í»§ÔÚ½ÓÏÂÀ´µÄ¼¸ÖÜÄÚÎÞ·¨¸¶¿î»ò»á¼ûÆäÔÚÏßÕË»§¡£¡£¡£LoanDepot Êǽü¼¸¸öÔÂÀ´Ôâµ½¶ñÒâºÚ¿Í¹¥»÷µÄ¼¸¼Ò´û¿îºÍµäÖÊ´û¿î¹«Ë¾Ö®Ò»¡£¡£¡£


https://techcrunch.com/2024/02/26/loandepot-millions-sensitive-personal-data-ransomware/?&web_view=true


5. Çå¾²»ú¹¹ÖÒÑÔ Ubiquiti EdgeRouter Óû§×¢ÖØ APT28 µÄÍþв


2ÔÂ28ÈÕ£¬£¬£¬£¬£¬£¬ÔÚÒ»·ÝеÄÁªºÏ×ÉѯÖУ¬£¬£¬£¬£¬£¬ÃÀ¹úºÍÆäËû¹ú¼ÒµÄÍøÂçÇå¾²ºÍÇ鱨»ú¹¹±Þ²ß Ubiquiti EdgeRouter Óû§½ÓÄɱ£»£»£»£»£» £»£»¤²½·¥£¬£¬£¬£¬£¬£¬¼¸ÖÜǰִ·¨²¿·ÖÔÚ´úºÅΪ¡° Dying Ember¡±µÄÐж¯ÖдݻÙÁËÒ»¸öÓÉÊÜѬȾ·ÓÉÆ÷×é³ÉµÄ½©Ê¬ÍøÂç¡£¡£¡£¾Ý³Æ£¬£¬£¬£¬£¬£¬¸Ã½©Ê¬ÍøÂçÃûΪ MooBot£¬£¬£¬£¬£¬£¬±»Óë¶íÂÞ˹ÓÐ¹ØµÄ APT28 Íþв×éÖ¯ÓÃÀ´¹¥»÷»î¶¯£¬£¬£¬£¬£¬£¬²¢Í¶·Å×Ô½ç˵¶ñÒâÈí¼þÒÔ¹©ºóÐøÊ¹Óᣡ£¡£¾ÝÏàʶ£¬£¬£¬£¬£¬£¬APT28 Á¥ÊôÓÚ¶íÂÞ˹×ÜÕÕÁϲ¿ (GRU)£¬£¬£¬£¬£¬£¬ÖÁÉÙ×Ô 2007 ÄêÒÔÀ´¾ÍÒ»Ö±»îÔ¾¡£¡£¡£MooBot ¹¥»÷ÐèÒªÒÔĬÈÏ»òÈõƾ֤µÄ·ÓÉÆ÷ΪĿµÄÀ´°²ÅÅ OpenSSH ľÂí£¬£¬£¬£¬£¬£¬APT28 »ñÈ¡´Ë»á¼ûȨÏÞÒÔÌṩ bash ¾ç±¾ºÍÆäËû ELF ¶þ½øÖÆÎļþÀ´ÍøÂçÆ¾Ö¤¡¢ÊðÀíÍøÂçÁ÷Á¿¡¢Ö÷»úÍøÂç´¹ÂÚÒ³ÃæºÍÆäËû¹¤¾ß¡£¡£¡£ÆäÖаüÀ¨ÓÃÓÚÉÏ´«ÊôÓÚÌØ¶¨Ä¿µÄÍøÂçÓʼþÓû§µÄÕÊ»§Æ¾Ö¤µÄ Python ¾ç±¾£¬£¬£¬£¬£¬£¬ÕâЩƾ֤ÊÇͨ¹ý¿çÕ¾µã¾ç±¾ºÍä¯ÀÀÆ÷ÖеÄä¯ÀÀÆ÷ ( BitB ) Óã²æÊ½ÍøÂç´¹ÂÚ»î¶¯ÍøÂçµÄ¡£¡£¡£


https://thehackernews.com/2024/02/cybersecurity-agencies-warn-ubiquiti.html


6. ¿ªÔ´ Xeno RAT ľÂí³ÉΪ GitHub ÉϵÄDZÔÚÍþв


2ÔÂ27ÈÕ£¬£¬£¬£¬£¬£¬Ò»ÖÖÃûΪXeno RATµÄ¡°È«ÐÄÉè¼Æ¡±µÄÔ¶³Ì»á¼ûľÂí (RAT)ÒÑÔÚ GitHub ÉÏÐû²¼£¬£¬£¬£¬£¬£¬ÆäËû¼ÓÈëÕßÎÞÐèÌØÊ⸶·Ñ¼´¿ÉʹÓøÃľÂí¡£¡£¡£¸Ã¿ªÔ´ RAT ½ÓÄÉ C# ±àд£¬£¬£¬£¬£¬£¬Óë Windows 10 ºÍ Windows 11 ²Ù×÷ϵͳ¼æÈÝ£¬£¬£¬£¬£¬£¬Å䱸ÁË¡°ÓÃÓÚÔ¶³ÌϵͳÖÎÀíµÄÖÜÈ«¹¦Ð§¡±£¬£¬£¬£¬£¬£¬Æä¿ª·¢Ö°Ô±£¨ÆäÃû³ÆÎª moom825£©ÌåÏÖ¡£¡£¡£Ëü°üÀ¨ SOCKS5 ·´ÏòÊðÀíºÍÂ¼ÖÆÊµÊ±ÒôƵµÄ¹¦Ð§£¬£¬£¬£¬£¬£¬²¢Á¬ÏµDarkVNC µÄÒþ²ØÐéÄâÍøÂçÅÌËã (hVNC) Ä£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬Ê¹¹¥»÷ÕßÄܹ»Ô¶³Ì»á¼ûÊÜѬȾµÄÅÌËã»ú¡£¡£¡£ÖµµÃ×¢ÖØµÄÊÇ£¬£¬£¬£¬£¬£¬moom825 Ò²ÊÇÁíÒ»ÖÖÃûΪDiscordRAT 2.0µÄ»ùÓÚ C# µÄ RAT µÄ¿ª·¢Õߣ¬£¬£¬£¬£¬£¬¸Ã RAT ÒÑÓÉÍþвÐÐΪÕßÔÚÃûΪ node-hide-console-windows µÄ¶ñÒâ npm °üÖзַ¢£¬£¬£¬£¬£¬£¬ÕýÈçReversingLabs ÓÚ 2023 Äê 10 ÔÂÅû¶µÄÄÇÑù¡£¡£¡£


https://thehackernews.com/2024/02/open-source-xeno-rat-trojan-emerges-as.html?&web_view=true